Intel 471 Malware Intelligence to Sentinel

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Content Index


This playbook ingests malware indicators from Intel 471's Titan or Verity API into Microsoft Sentinel as tiIndicator resource type.

Attribute Value
Type Playbook
Solution Intel471
Source View on GitHub

Logic App Connectors

This playbook uses 4 Logic App connectors / built-in actions:

Connector / Action Type Connections Actions
azureblob Managed 1 5
azuresentinel Managed 1 1
keyvault Managed 1 2
http Built-in 0 1
Action parameters (URLs, paths, function IDs)

azureblob (Managed)

Action Method Endpoint Other
StoreCursor put /v2/datasets/@{uriComponent(uriComponent(parameters('StorageAccountName')))}/files/@{uriComponent(uriComponent(parameters('StorageAccountContainerName'),'/',parameters('BlobNameCursor')))} —
GetCursorFromBlob get /v2/datasets/@{uriComponent(uriComponent(parameters('StorageAccountName')))}/files/@{uriComponent(uriComponent(parameters('StorageAccountContainerName'),'/',parameters('BlobNameCursor')))}/content —
GetFromDateFromBlob get /v2/datasets/@{uriComponent(uriComponent(parameters('StorageAccountName')))}/files/@{uriComponent(uriComponent(parameters('StorageAccountContainerName'),'/',parameters('BlobNameFromDate')))}/content —
CreateBlobForCursor post /v2/datasets/@{uriComponent(uriComponent(parameters('StorageAccountName')))}/files —
CreateBlobForFromDate post /v2/datasets/@{uriComponent(uriComponent(parameters('StorageAccountName')))}/files —

azuresentinel (Managed)

Action Method Endpoint Other
Threat_Intelligence_-Upload_STIX_Objects(Preview) post /ThreatIntelligence/@{encodeURIComponent(uriComponent(parameters('WorkspaceID')))}/UploadStixObjects/ —

keyvault (Managed)

Action Method Endpoint Other
GetApiKey get /secrets/@{encodeURIComponent(parameters('ApiKeySecretName'))}/value —
GetUsername get /secrets/@{encodeURIComponent(parameters('UsernameSecretName'))}/value —

http (Built-in)

Action Method Endpoint Other
HTTP GET @parameters('ApiURI') —

Additional Documentation

📄 Source: Intel471-ImportMalwareIntelligenceToSentinel/readme.md

Intel 471 Malware Intelligence import to Sentinel

Table of contents

  1. Overview
  2. Prerequisites
  3. Getting your Intel 471 API credentials
  4. Storage account requirements
  5. Deployment instructions
  6. Post-deployment instructions
  7. Upgrading from version 2.0.0
  8. Querying Intel 471 Malware Intelligence data in Sentinel
  9. Data mapping

Overview

This playbook fetches malware intelligence indicators from the Intel 471's Titan or Verity API and ingests them using Threat Intelligence UploadStixObjects API for Microsoft Sentinel.

azuredeploy.json Azure Resource Manager template (ARM template) is responsible for building the Logic App along with the necessary connections. The ARM builds following components:

Note: installing the Intel 471 solution from the Microsoft Sentinel Content hub does not create the logic app. The solution installs the playbook templates; the logic app is created when you deploy a playbook from Content hub → Intel 471 → Manage → Create playbook, or from Microsoft Sentinel → Automation → Playbook templates. Deploying azuredeploy.json directly, as described below, creates it in one step.

Prerequisites

  1. An active account in Titan or Verity platform, which is available as part of Intel 471's subscriptions. For more information, please contact sales@intel471.com.

  2. Titan or Verity API credentials - see Getting your Intel 471 API credentials.

  3. Pre-existing Key Vault for securely storing the API credentials. By default the playbook reads:

    | Backend | User name secret | API key secret | | ------- | ---------------- | -------------- | | Titan | TitanUserNameSentinel | TitanAPIKeySentinel | | Verity | VerityUserNameSentinel | VerityAPIKeySentinel |

    If your organisation already stores these credentials under different names, leave the secrets where they are and pass the names of those secrets in the optional KeyVaultUsernameSecretName and KeyVaultApiKeySecretName deployment parameters instead. Those two parameters take secret names, never credential values.

  4. Pre-existing Storage account with a blob container, for persisting data such as the cursor between API calls. Default settings are fine - see Storage account requirements.

  5. Threat Intelligence connector enabled in Sentinel. Go to Sentinel instance → Content hub and install Threat Intelligence solution.

Getting your Intel 471 API credentials

The playbook authenticates to the Intel 471 API with HTTP Basic authentication. Which two values you need depends on the backend you select at deployment.

Verity (Backend = Verity)

Verity issues an API Client ID and an API Client Secret. There is no separate "user name" or "API key" to look for - the Client ID is sent as the Basic user name and the Client Secret as the Basic password. Store them like this:

Verity portal value Key Vault secret (default name)
API Client ID VerityUserNameSentinel
API Client Secret VerityAPIKeySentinel

To obtain them, sign in to the Intel 471 portal, open your account/API settings and create an API client. Copy the Client Secret at creation time - it is not shown again. If you do not see the option, or the indicators stream returns 403, your subscription may not include API access; contact support@intel471.com.

Titan (Backend = Titan)

Titan uses your account email as the Basic user name and an API key as the Basic password. Generate the API key at portal.intel471.com/api.

[Content truncated...]


Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Playbooks · Back to Intel471